Free5Gc · Free5Gc · CVE-2023-47346
**Name of the Vulnerable Software and Affected Versions**
free5gc version 3.3.0
UPF version 1.2.0
SMF version 1.2.0
**Description**
The issue allows attackers to cause a denial of service via crafted PFCP messages. This is a Buffer Overflow vulnerability.
**Recommendations**
For free5gc version 3.3.0, update to a version that fixes the Buffer Overflow vulnerability.
For UPF version 1.2.0, update to a version that fixes the Buffer Overflow vulnerability.
For SMF version 1.2.0, update to a version that fixes the Buffer Overflow vulnerability.
As a temporary workaround, consider restricting the use of crafted PFCP messages to minimize the risk of exploitation.